CVE-2024-35648: WordPress Emergency Password Reset plugin <= 8.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery.
This issue affects Emergency Password Reset: from n/a through 8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Emergency Password Reset pluginto a version that resolves this vulnerability.Fixed in 9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35648?
The severity of CVE-2024-35648 is medium with a score of 4.3.
What impact does CVE-2024-35648 have?
CVE-2024-35648 can lead to unauthorized actions due to Cross Site Request Forgery (CSRF).
How do I fix CVE-2024-35648?
To fix CVE-2024-35648, update the Emergency Password Reset plugin to version 8.1 or higher.
Which versions are affected by CVE-2024-35648?
CVE-2024-35648 affects Emergency Password Reset plugin versions n/a through 8.0.
What type of vulnerability is CVE-2024-35648?
CVE-2024-35648 is classified as a Cross Site Request Forgery (CSRF) vulnerability.